Skip to main content
PUT
Settle who a published share is for

Autorizaciones

Authorization
string
header
requerido

Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.

Parámetros de ruta

shareId
string
requerido

The share's id, as SessionShare.shareId reports it: 26 characters of RFC 4648 base32 drawn from a cryptographic source, carrying no encoding of anything. It is NOT a uuid and is deliberately unrelated to the session id it was published from — a share id travels, so an id derived from a session would make every leaked link a statement about the machine it came from.

Required string length: 26
Pattern: ^[A-Z2-7]{26}$

Cuerpo

application/json

Who a published share is for, after this request. THE WHOLE LIST AND NOT A CHANGE TO ONE. What is sent is what the share names afterwards, so adding a colleague and removing another is a single act with a single answer — a body that carried "add these, remove those" would be two lists that can contradict each other and a third rule for what happens when they do. ABSENT OR EMPTY IS THE WHOLE ORGANISATION, the ordinary publish and the default — never "a share nobody may read". It is how a share narrowed by mistake is widened again without republishing the conversation. Naming somebody twice is the same grant said twice and is kept once. A value no sign-in could report — a blank, a pasted line — is refused by name with 422, because a share addressed to a typo is a share readable by nobody answered with a success.

recipients
string[]

The subjects of the colleagues this share is for. They are members of the same organisation: there is no cross-organisation share, because one organisation is one home and a token for another is refused before any handler runs.

Respuesta

The share is for exactly the colleagues named, at this home and at the organisation's.